Thank you for your great help. I collected the logs as you requested. I do
not know how to attach the files and I seperatethem into two post:
PartI_DCDIAG LOG AND ERROR LOG IN THIS POST Sorry that it is too long...
Thanks for your generous time and help.
Part I: The DCdiag AND ERROR log on this rootdomaincontroller1:
**Part II: The Dcdiag log on this rootdomaincontrollername1
Domain Controller Diagnosis
Performing initial setup:
* Verifying that the local machine rootdomaincontrollerName, is a DC.
* Connecting to directory service on server rootdomaincontrollerName.
* Collecting site info.
* Identifying all servers.
* Identifying all NC cross-refs.
* Found 4 DC(s). Testing 1 of them.
Done gathering initial info.
Doing initial required tests
Testing server: Site1\rootdomaincontrollerName
Starting test: Connectivity
* Active Directory LDAP Services Check
* Active Directory RPC Services Check
......................... rootdomaincontrollerName passed test
Connectivity
Doing primary tests
Testing server: Site1\rootdomaincontrollerName
Starting test: Replications
* Replications Check
[Replications Check,rootdomaincontrollerName] A recent replication
attempt failed:
From childdomaincontrollerName1 to rootdomaincontrollerName
Naming Context: CN=Schema,CN=Configuration,DC=Internal,DC=Local
The replication generated an error (5):
Access is denied.
The failure occurred at 2008-06-16 12:46:29.
The last success occurred at 2007-10-04 11:46:34.
6024 failures have occurred since the last success.
[childdomaincontrollerName1] DsBindWithSpnEx() failed with error 5,
Access is denied..
[Replications Check,rootdomaincontrollerName] A recent replication
attempt failed:
From childdomaincontrollerName2 to rootdomaincontrollerName
Naming Context: CN=Schema,CN=Configuration,DC=Internal,DC=Local
The replication generated an error (5):
Access is denied.
The failure occurred at 2008-06-16 12:46:29.
The last success occurred at 2007-10-04 09:46:13.
6026 failures have occurred since the last success.
[childdomaincontrollerName2] DsBindWithSpnEx() failed with error 5,
Access is denied..
[Replications Check,rootdomaincontrollerName] A recent replication
attempt failed:
From childdomaincontrollerName3 to rootdomaincontrollerName
Naming Context: CN=Schema,CN=Configuration,DC=Internal,DC=Local
The replication generated an error (5):
Access is denied.
The failure occurred at 2008-06-16 12:46:29.
The last success occurred at 2007-10-04 11:46:55.
6024 failures have occurred since the last success.
[childdomaincontrollerName3] DsBindWithSpnEx() failed with error 5,
Access is denied..
[Replications Check,rootdomaincontrollerName] A recent replication
attempt failed:
From childdomaincontrollerName2 to rootdomaincontrollerName
Naming Context: CN=Configuration,DC=Internal,DC=Local
The replication generated an error (5):
Access is denied.
The failure occurred at 2008-06-16 12:46:29.
The last success occurred at 2007-10-04 11:58:34.
6024 failures have occurred since the last success.
[Replications Check,rootdomaincontrollerName] A recent replication
attempt failed:
From childdomaincontrollerName3 to rootdomaincontrollerName
Naming Context: CN=Configuration,DC=Internal,DC=Local
The replication generated an error (5):
Access is denied.
The failure occurred at 2008-06-16 12:46:29.
The last success occurred at 2007-10-04 12:04:11.
6024 failures have occurred since the last success.
[Replications Check,rootdomaincontrollerName] A recent replication
attempt failed:
From childdomaincontrollerName1 to rootdomaincontrollerName
Naming Context: CN=Configuration,DC=Internal,DC=Local
The replication generated an error (5):
Access is denied.
The failure occurred at 2008-06-16 12:46:29.
The last success occurred at 2007-10-04 11:58:42.
6623 failures have occurred since the last success.
[Replications Check,rootdomaincontrollerName] A recent replication
attempt failed:
From childdomaincontrollerName2 to rootdomaincontrollerName
Naming Context: DC=ForestDnsZones,DC=Internal,DC=Local
The replication generated an error (1256):
The remote system is not available. For information about
network troubleshooting, see Windows Help.
The failure occurred at 2008-06-16 12:46:29.
The last success occurred at 2007-10-04 11:55:00.
6024 failures have occurred since the last success.
[Replications Check,rootdomaincontrollerName] A recent replication
attempt failed:
From childdomaincontrollerName1 to rootdomaincontrollerName
Naming Context: DC=ForestDnsZones,DC=Internal,DC=Local
The replication generated an error (1256):
The remote system is not available. For information about
network troubleshooting, see Windows Help.
The failure occurred at 2008-06-16 12:46:29.
The last success occurred at 2007-10-04 11:55:21.
6037 failures have occurred since the last success.
* Replication Latency Check
REPLICATION-RECEIVED LATENCY WARNING
rootdomaincontrollerName: Current time is 2008-06-16 13:02:32.
CN=Schema,CN=Configuration,DC=Internal,DC=Local
Last replication recieved from childdomaincontrollerName1 at
2007-10-04 11:46:34.
WARNING: This latency is over the Tombstone Lifetime of 60
days!
Last replication recieved from childdomaincontrollerName3 at
2007-10-04 11:46:55.
WARNING: This latency is over the Tombstone Lifetime of 60
days!
Latency information for 25 entries in the vector were ignored.
24 were retired Invocations. 0 were either: read-only
replicas and are not verifiably latent, or dc's no longer replicating this
nc. 1 had no latency information (Win2K DC).
CN=Configuration,DC=Internal,DC=Local
Last replication recieved from childdomaincontrollerName2 at
2007-10-04 11:58:39.
WARNING: This latency is over the Tombstone Lifetime of 60
days!
Last replication recieved from childdomaincontrollerName1 at
2007-10-04 11:58:42.
WARNING: This latency is over the Tombstone Lifetime of 60
days!
Last replication recieved from childdomaincontrollerName3 at
2007-10-04 12:04:11.
WARNING: This latency is over the Tombstone Lifetime of 60
days!
Latency information for 25 entries in the vector were ignored.
25 were retired Invocations. 0 were either: read-only
replicas and are not verifiably latent, or dc's no longer replicating this
nc. 0 had no latency information (Win2K DC).
DC=ForestDnsZones,DC=Internal,DC=Local
Last replication recieved from childdomaincontrollerName2 at
2007-10-04 11:53:15.
WARNING: This latency is over the Tombstone Lifetime of 60
days!
Last replication recieved from childdomaincontrollerName1 at
2007-10-04 11:55:21.
WARNING: This latency is over the Tombstone Lifetime of 60
days!
Latency information for 6 entries in the vector were ignored.
6 were retired Invocations. 0 were either: read-only
replicas and are not verifiably latent, or dc's no longer replicating this
nc. 0 had no latency information (Win2K DC).
DC=DomainDnsZones,DC=Internal,DC=Local
Latency information for 4 entries in the vector were ignored.
4 were retired Invocations. 0 were either: read-only
replicas and are not verifiably latent, or dc's no longer replicating this
nc. 0 had no latency information (Win2K DC).
DC=Internal,DC=Local
Latency information for 14 entries in the vector were ignored.
14 were retired Invocations. 0 were either: read-only
replicas and are not verifiably latent, or dc's no longer replicating this
nc. 0 had no latency information (Win2K DC).
* Replication Site Latency Check
......................... rootdomaincontrollerName passed test
Replications
Test omitted by user request: Topology
Test omitted by user request: CutoffServers
Starting test: NCSecDesc
* Security Permissions check for all NC's on DC
rootdomaincontrollerName.
* Security Permissions Check for
DC=ForestDnsZones,DC=Internal,DC=Local
(NDNC,Version 2)
* Security Permissions Check for
DC=DomainDnsZones,DC=Internal,DC=Local
(NDNC,Version 2)
* Security Permissions Check for
CN=Schema,CN=Configuration,DC=Internal,DC=Local
(Schema,Version 2)
* Security Permissions Check for
CN=Configuration,DC=Internal,DC=Local
(Configuration,Version 2)
* Security Permissions Check for
DC=Internal,DC=Local
(Domain,Version 2)
......................... rootdomaincontrollerName passed test
NCSecDesc
Starting test: NetLogons
* Network Logons Privileges Check
Verified share \\rootdomaincontrollerName\netlogon
Verified share \\rootdomaincontrollerName\sysvol
......................... rootdomaincontrollerName passed test
NetLogons
Starting test: Advertising
Fatal Error:DsGetDcName (rootdomaincontrollerName) call failed,
error 1355
The Locator could not find the server.
......................... rootdomaincontrollerName failed test
Advertising
Starting test: KnowsOfRoleHolders
Role Schema Owner = CN=NTDS
Settings,CN=rootdomaincontrollerName,CN=Servers,CN=Site1,CN=Sites,CN=Configuration,DC=Internal,DC=Local
Role Domain Owner = CN=NTDS
Settings,CN=rootdomaincontrollerName,CN=Servers,CN=Site1,CN=Sites,CN=Configuration,DC=Internal,DC=Local
Role PDC Owner = CN=NTDS
Settings,CN=rootdomaincontrollerName,CN=Servers,CN=Site1,CN=Sites,CN=Configuration,DC=Internal,DC=Local
Role Rid Owner = CN=NTDS
Settings,CN=rootdomaincontrollerName,CN=Servers,CN=Site1,CN=Sites,CN=Configuration,DC=Internal,DC=Local
Role Infrastructure Update Owner = CN=NTDS
Settings,CN=rootdomaincontrollerName,CN=Servers,CN=Site1,CN=Sites,CN=Configuration,DC=Internal,DC=Local
......................... rootdomaincontrollerName passed test
KnowsOfRoleHolders
Starting test: RidManager
* Available RID Pool for the Domain is 10613 to 1073741823
* rootdomaincontrollerName.Internal.Local is the RID Master
* DsBind with RID Master was successful
* rIDAllocationPool is 10113 to 10612
* rIDPreviousAllocationPool is 10113 to 10612
* rIDNextRID: 10114
......................... rootdomaincontrollerName passed test
RidManager
Starting test: MachineAccount
Checking machine account for DC rootdomaincontrollerName on DC
rootdomaincontrollerName.
* SPN found
:LDAP/rootdomaincontrollerName.Internal.Local/Internal.Local
* SPN found :LDAP/rootdomaincontrollerName.Internal.Local
* SPN found :LDAP/rootdomaincontrollerName
* SPN found :LDAP/rootdomaincontrollerName.Internal.Local/EISNER
* SPN found
:LDAP/06e8d104-237a-4ee2-b28a-f1498e59d563._msdcs.Internal.Local
* SPN found
:E3514235-4B06-11D1-AB04-00C04FC2DCD2/06e8d104-237a-4ee2-b28a-f1498e59d563/Internal.Local
* SPN found
:HOST/rootdomaincontrollerName.Internal.Local/Internal.Local
* SPN found :HOST/rootdomaincontrollerName.Internal.Local
* SPN found :HOST/rootdomaincontrollerName
* SPN found :HOST/rootdomaincontrollerName.Internal.Local/EISNER
* SPN found
:GC/rootdomaincontrollerName.Internal.Local/Internal.Local
......................... rootdomaincontrollerName passed test
MachineAccount
Starting test: Services
* Checking Service: Dnscache
* Checking Service: NtFrs
* Checking Service: IsmServ
* Checking Service: kdc
* Checking Service: SamSs
* Checking Service: LanmanServer
* Checking Service: LanmanWorkstation
* Checking Service: RpcSs
* Checking Service: w32time
* Checking Service: NETLOGON
NETLOGON Service is paused on [rootdomaincontrollerName]
......................... rootdomaincontrollerName failed test
Services
Test omitted by user request: OutboundSecureChannels
Starting test: ObjectsReplicated
rootdomaincontrollerName is in domain DC=Internal,DC=Local
Checking for CN=rootdomaincontrollerName,OU=Domain
Controllers,DC=Internal,DC=Local in domain DC=Internal,DC=Local on 1 servers
Object is up-to-date on all servers.
Checking for CN=NTDS
Settings,CN=rootdomaincontrollerName,CN=Servers,CN=Site1,CN=Sites,CN=Configuration,DC=Internal,DC=Local
in domain CN=Configuration,DC=Internal,DC=Local on 1 servers
Object is up-to-date on all servers.
......................... rootdomaincontrollerName passed test
ObjectsReplicated
Starting test: frssysvol
* The File Replication Service SYSVOL ready test
File Replication Service's SYSVOL is ready
......................... rootdomaincontrollerName passed test
frssysvol
Starting test: frsevent
* The File Replication Service Event log test
......................... rootdomaincontrollerName passed test
frsevent
Starting test: kccevent
* The KCC Event log test
An Warning Event occured. EventID: 0x80000677
Time Generated: 06/16/2008 12:59:54
(Event String could not be retrieved)
An Error Event occured. EventID: 0xC0000466
Time Generated: 06/16/2008 12:59:54
(Event String could not be retrieved)
An Warning Event occured. EventID: 0x80000786
Time Generated: 06/16/2008 12:59:54
Event String: The attempt to establish a replication link to
aread-only directory partition with the followingparameters failed.
Directory partition: DC=us,DC=Internal,DC=Local Source domain controller:
CN=NTDS
Settings,CN=childdomaincontrollerName1,CN=Servers,CN=Site1,CN=Sites,CN=Configuration,DC=Internal,DC=Local
Source domain controller address:
9abdc27e-3791-4382-9878-fd51c761f90c._msdcs.Internal.Local Intersite
transport (if any): Additional Data Error value: 5 Access is denied.
An Warning Event occured. EventID: 0x80000786
Time Generated: 06/16/2008 12:59:54
Event String: The attempt to establish a replication link to
aread-only directory partition with the followingparameters failed.
Directory partition: DC=us,DC=Internal,DC=Local Source domain controller:
CN=NTDS
Settings,CN=childdomaincontrollerName2,CN=Servers,CN=Site1,CN=Sites,CN=Configuration,DC=Internal,DC=Local
Source domain controller address:
1395049a-a8cc-4a44-98a0-f53eb8e5239f._msdcs.Internal.Local Intersite
transport (if any): Additional Data Error value: 5 Access is denied.
An Warning Event occured. EventID: 0x80000786
Time Generated: 06/16/2008 12:59:54
Event String: The attempt to establish a replication link to
aread-only directory partition with the followingparameters failed.
Directory partition: DC=us,DC=Internal,DC=Local Source domain controller:
CN=NTDS
Settings,CN=childdomaincontrollerName3,CN=Servers,CN=Site1,CN=Sites,CN=Configuration,DC=Internal,DC=Local
Source domain controller address:
56ae8abc-0a16-4665-8a15-e5956de88afc._msdcs.Internal.Local Intersite
transport (if any): Additional Data Error value: 5 Access is denied.
An Warning Event occured. EventID: 0x80000677
Time Generated: 06/16/2008 13:02:10
(Event String could not be retrieved)
An Error Event occured. EventID: 0xC0000466
Time Generated: 06/16/2008 13:02:10
(Event String could not be retrieved)
An Warning Event occured. EventID: 0x80000677
Time Generated: 06/16/2008 13:03:43
(Event String could not be retrieved)
An Error Event occured. EventID: 0xC0000466
Time Generated: 06/16/2008 13:03:43
(Event String could not be retrieved)
......................... rootdomaincontrollerName failed test
kccevent
Starting test: systemlog
* The System Event log test
Found no errors in System Event log in the last 60 minutes.
......................... rootdomaincontrollerName passed test
systemlog
Test omitted by user request: VerifyReplicas
Starting test: VerifyReferences
The system object reference (serverReference)
CN=rootdomaincontrollerName,OU=Domain Controllers,DC=Internal,DC=Local and
backlink on
CN=rootdomaincontrollerName,CN=Servers,CN=Site1,CN=Sites,CN=Configuration,DC=Internal,DC=Local are correct.
The system object reference (frsComputerReferenceBL)
CN=rootdomaincontrollerName,CN=Domain System Volume (SYSVOL share),CN=File
Replication Service,CN=System,DC=Internal,DC=Local and backlink on
CN=rootdomaincontrollerName,OU=Domain Controllers,DC=Internal,DC=Local
are correct.
The system object reference (serverReferenceBL)
CN=rootdomaincontrollerName,CN=Domain System Volume (SYSVOL share),CN=File
Replication Service,CN=System,DC=Internal,DC=Local and backlink on
CN=NTDS
Settings,CN=rootdomaincontrollerName,CN=Servers,CN=Site1,CN=Sites,CN=Configuration,DC=Internal,DC=Local are correct.
......................... rootdomaincontrollerName passed test
VerifyReferences
Test omitted by user request: VerifyEnterpriseReferences
Test omitted by user request: CheckSecurityError
Running partition tests on : ForestDnsZones
Starting test: CrossRefValidation
......................... ForestDnsZones passed test
CrossRefValidation
Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRefDom
Running partition tests on : DomainDnsZones
Starting test: CrossRefValidation
......................... DomainDnsZones passed test
CrossRefValidation
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom
Running partition tests on : Schema
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Running partition tests on : Configuration
Starting test: CrossRefValidation
......................... Configuration passed test
CrossRefValidation
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom
Running partition tests on : eisner
Starting test: CrossRefValidation
......................... eisner passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... eisner passed test CheckSDRefDom
Running enterprise tests on : Internal.Local
Starting test: Intersite
Skipping site Site1, this site is outside the scope provided by the
command line arguments provided.
......................... Internal.Local passed test Intersite
Starting test: FsmoCheck
[childdomaincontrollerName2] LDAP bind failed with error 1323,
Unable to update the password. The value provided as the current
password is incorrect..
Warning: Couldn't verify this server as a GC in this servers AD.
GC Name: \\childdomaincontrollerName2.us.Internal.Local
Locator Flags: 0xe00001bc
PDC Name: \\rootdomaincontrollerName.Internal.Local
Locator Flags: 0xe00003f9
Warning: DcGetDcName(TIME_SERVER) call failed, error 1355
A Time Server could not be located.
The server holding the PDC role is down.
Warning: DcGetDcName(GOOD_TIME_SERVER_PREFERRED) call failed, error
1355
A Good Time Server could not be located.
Warning: DcGetDcName(KDC_REQUIRED) call failed, error 1355
A KDC could not be located - All the KDCs are down.
......................... Internal.Local failed test FsmoCheck
Test omitted by user request: DNS
Test omitted by user request: DNS
________________________________________________
PartIII error messages:
In the Application Log:
Event Type: Error
Event Source: Userenv
Event Category: None
Event ID: 1054
Date: 6/16/2008
Time: 12:58:43 PM
User: NT AUTHORITY\SYSTEM
Computer: Rootdomaincontroller1
Description:
Windows cannot obtain the domain controller name for your computer network.
(The specified domain either does not exist or could not be contacted. ).
Group Policy processing aborted.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
____________________________________________________________________________________-
In the Directory service Log:
Event Type: Error
Event Source: NTDS General
Event Category: Global Catalog
Event ID: 1126
Date: 6/16/2008
Time: 1:03:43 PM
User: NT AUTHORITY\ANONYMOUS LOGON
Computer: Rootdomaincontroller1
Description:
Active Directory was unable to establish a connection with the global
catalog.
Additional Data
Error value:
1355 The specified domain either does not exist or could not be contacted.
Internal ID:
3200d33
User Action:
Make sure a global catalog is available in the forest, and is reachable from
this domain controller. You may use the nltest utility to diagnose this
problem.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
_________________________________________________________________________________________________________________
Event Type: Warning
Event Source: NTDS General
Event Category: Global Catalog
Event ID: 1655
Date: 6/16/2008
Time: 1:03:43 PM
User: NT AUTHORITY\ANONYMOUS LOGON
Computer: Rootdomaincontroller1
Description:
Active Directory attempted to communicate with the following global catalog
and the attempts were unsuccessful.
Global catalog:
\\Childdomaincontroller3.us.internal.local
The operation in progress might be unable to continue. Active Directory will
use the domain controller locator to try to find an available global catalog
server.
Additional Data
Error value:
5 Access is denied.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
"Meinolf Weber" wrote:
| Quote: |
Hello John,
So the server has no physical crash? Please post the complete error messages
from the event viewer. Also post a complete output from dcdiag /v and netdiag
/v
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
Thank you for your help.
I have one forest with one empty root domain (one domain controller)
and one child domain (2 domain controllers) that holds users and
servers.
unfortunately, only one domain controller for the root domain and no
backup?
"Meinolf Weber" wrote:
Hello John,
Please describe in detail how many dc's you have and the complete
domain setup. Do you have subdomains, because you talk about root
domain?
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and
confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
Hi all,
The domain controller of root domain has been crashed. I do not
know
how long it has been down. Finally, I rebooted the server and came
online. I tried to add the second domain controller but can not.
then I tried to join the PC to this domain and can not which no
domain
controller found. I got these events in the direcory services:
event
id 1645 with source NTDS replication, event id 1126 with source
global catalog,....I run dcdiag and fsmo failed check.
Is there a way I can make this domain controller recognized by this
domain without wiping out everything? (windows 2003 R2 SP2)
|